Skip to content

RANGER-5742: Inconsistent handling of service config fields by name v… - #1152

Open
vyommani wants to merge 1 commit into
apache:masterfrom
vyommani:RANGER-5742
Open

RANGER-5742: Inconsistent handling of service config fields by name v…#1152
vyommani wants to merge 1 commit into
apache:masterfrom
vyommani:RANGER-5742

Conversation

@vyommani

Copy link
Copy Markdown
Contributor

What changes were proposed in this pull request?

Service config masking (read) and encryption (write) previously only matched the literal key "password". Service-defs can declare other config items with type="password" under different names (e.g. NiFi's nifi.ssl.keystorePassword /truststorePassword) - those were left unmasked/unencrypted.

This change treats any config item as a secret if its key is "password" OR the service-def declares it with type="password", applied consistently across RangerServiceService (read/view) and ServiceDBStore (create/update). updateService now preserves the correct per-key value on the hidden-sentinel case instead of a single shared variable. Shared classification logic lives in one place (ServiceDBStore) to avoid drift.

How was this patch tested?

Added/updated unit tests in TestRangerServiceService and TestServiceDBStore covering masking, encryption, and per-key update behavior for service-def-declared secret keys.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant